Prosecution Insights
Last updated: August 15, 2026
Application No. 18/186,381

SYSTEMS AND METHODS FOR DETECTING ANOMALOUS BEHAVIOR IN INTERNET-OF-THINGS (IOT) DEVICES

Non-Final OA §103
Filed
Mar 20, 2023
Examiner
LIPMAN, JACOB
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Acronis International GmbH
OA Round
5 (Non-Final)
83%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
671 granted / 806 resolved
+25.3% vs TC avg
Moderate +12% lift
Without
With
+12.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
19 currently pending
Career history
825
Total Applications
across all art units

Statute-Specific Performance

§101
4.3%
-35.7% vs TC avg
§103
42.4%
+2.4% vs TC avg
§102
27.1%
-12.9% vs TC avg
§112
18.2%
-21.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 806 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20, are rejected under 35 U.S.C. 103 as being unpatentable over Howlett et al., USPN 2021/0273949, in view of Lei et al., CN 113904797A, as outlined with provided translation, in further view of Dean et al., USPN 2020/0280575. With regard to claims 1, 12 and 20, Howlett discloses a method for detecting anomalous behavior in devices within a network (0006), the method including identifying, from a first plurality of packets intercepted in a network, a subset of packets corresponding to a first device of a plurality of devices in the network (0050-0052, 0146-0151), extracting a plurality of deterministic features from the subset of packets (0148, 0139, 0146-0147), determining a deviation of the plurality of deterministic features from a deterministic profile of the first device (0148, 0068, 0107, 0147), wherein the deterministic profile includes features representing a normal behavioral pattern of the first device (0148, 0068, 0107, 0147), determining a first probability of anomalous behavior from the first device by inputting a first feature vector including device-specific traffic information generated from the subset of packets into a first device anomaly model for the first device (0146, 0036), wherein the first device anomaly model is one of a plurality of device anomaly models (0146, “one or more Artificial Intelligence models each trained on different users, devices” 0036, 0041, 0044), and wherein the first device anomaly model excludes traffic or features from any other device (the model from that specific device 0036, 0044, 0046), determining a second probability of anomalous behavior in the network by inputting the second feature vector including network-specific traffic information generated from the first plurality of packets into a network anomaly model (0147-0149), calculating a risk score associated with the first device as a function of (i) the deviation,(ii) the first probability output by the first device anomaly model (0128-0129), and (iii) the second probability output by the network anomaly model, computed contemporaneously from traffic observed in a common analysis window (0136, 0141-0149, 0128-0129), determining, using an attack classification model, an attack type of the first device, wherein the attack classification model is retrained based on analyst feedback (0141, 0061, 0063, 0122), and executing a remediation action based on the attack type to resolve anomalous behavior in the first device in response to determining that the risk score is greater than a threshold risk score (0053, 0055, 0061, 0088, 0122-0128, 0140). Howlett does not disclose that the device is one of a plurality protected by the network. Lei discloses a method for detecting anomalous behavior in devices within a network (page 3 paragraph beginning “the purpose”), similar to that of Howlett, and further discloses the device is a part of an internet of things (page 3 paragraph beginning “to achieve”), and detecting behavior of one device (page 3 paragraph beginning “further, the IOT event”). It would have been obvious for one of ordinary skill in the art, prior to the instant effective filing date, to have the device of Howlett be one of several in an IOT, and the device specific packets be a subset of the total network packets, as taught by Lei, for the motivation of protecting each device in such as system. Howlett discloses “one or more Artificial Intelligence models each trained on different users, devices, system activities and interactions between entities in the system“ (0036), but Howlett in view of Lei does not specifically disclose that each anomaly model includes an individual model for a respective device of the plurality of devices trained using a device-specific training dataset. Dean discloses a method for detecting anomalous behavior in devices within a network using trained machine learning models (0006-0013, claim 28), similar to that of Howlett and Lei, and further discloses each anomaly model includes an individual model for a respective device of the plurality of devices trained using a device-specific training dataset (claim 28, 0012). It would have been obvious for one of ordinary skill in the art, prior to the instant effective filing date, to have each anomaly model includes an individual model for a respective device of the plurality of devices trained using a device-specific training dataset, as taught by Dean, in the method of Howlett in view of Lei, for the motivation of protecting each device in a unified manner and to utilize anomaly models based on violation category rather than historical behavior. With regard to claims 2 and 13, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the attack classification model is configured to classify an anomaly vector into a respective attack type (0141, 0061, 0063, 0122). With regard to claims 3 and 14, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses intercepting, during a training phase prior to intercepting the first plurality of packets, a second plurality of packets of the network over a period of time, identifying the plurality of devices in the network based on the second plurality of packets (0035-0038, 0041-0049). With regard to claims 4 and 15, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses for each respective device of the plurality of devices extracting deterministic features of the respective device from the second plurality of packets, generating a respective deterministic profile based on the extracted deterministic features of the respective device (0067, 0135, 0148, 0068, 0107, 0147). With regard to claims 5 and 16, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the extracted deterministic features of the respective device include one or more of: protocols used at different layers of a transmission control protocol (TCP) or internet protocol (IP) stack (0113-0115) With regard to claims 6 and 17, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, but do not disclose the respective deterministic profile is a hash table including hash values representing the extracted deterministic features. The examiner took official notice that it is well known in the art to store data as a hash table. Since this notice was not traversed, it is taken as admitted prior art (MPEP 2144.03). It would have been obvious for one of ordinary skill in the art, prior to the instant effective filing date, to store the profile of Howlett in view of Lei in further view of Dean as a hash table, for the motivation of saving space and reducing computation, a stated motivations of Howlett (0106, 0146) With regard to claims 7 and 18, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses generating, for each respective device of the plurality of devices, a device-specific training dataset including a plurality of feature vectors using the second plurality of packets, training, for each respective device of the plurality of devices, a respective device anomaly detection AI model using the device-specific training dataset, wherein the respective device anomaly detection AI model is configured to classify an input feature vector as anomalous or non-anomalous and output an associated probability (0036, 0049, 0062-0063), as does Lei (page 5 paragraph beginning “Referring to FIG 1”). With regard to claims 8 and 19, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses generating, for the network, a network-specific training dataset including a plurality of feature vectors labelled by anomalous or non-anomalous classes using the second plurality of packets, training, for the network, the network anomaly detection AI model using the network-specific training dataset, wherein the network anomaly detection AI model is configured to classify an input feature vector as anomalous or non-anomalous and output an associated probability (0036, 0049, 0062-0063), as does Lei (page 5 paragraph beginning “Referring to FIG 1”). With regard to claim 9, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the first feature vector includes, for the first device, one or more of: a size of each packet, time intervals between packets, semantic information of IP addresses and port numbers (0113-0115, 0037). With regard to claim 10, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the second feature vector includes, for the plurality of devices in the network, one or more of: a size of each packet, time intervals between packets, semantic information of IP addresses and port numbers (0113-0115, 0037). With regard to claim 11, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the remediation action includes one or more of: factory resetting the first device, rebooting the first device, transmitting an alert about the anomalous behavior of the first device to a network administrator of the network, limiting the access to the network by the first device, blocking/re-directing traffic of the first device, and removing the first device from the network (0053, 0147). Response to Arguments Applicant's arguments filed 10 March 2026 have been fully considered but they are not fully persuasive. The amendment overcame the prior rejection, but a new rejection was made, as outlined above. References Cited Oleson et al., USPN 2021/0350180, discloses a method for analyzing device data within a network using trained machine learning models (0022), similar to that of Howlett, Lei, and Dean, and further discloses each anomaly model is corresponding to and trained using only traffic of a respective different device from the plurality of devices (0072). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JACOB LIPMAN whose telephone number is (571)272-3837. The examiner can normally be reached 5:30AM-6:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JACOB LIPMAN/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Show 5 earlier events
Aug 13, 2025
Response after Non-Final Action
Sep 05, 2025
Non-Final Rejection mailed — §103
Dec 02, 2025
Response Filed
Dec 23, 2025
Final Rejection mailed — §103
Mar 10, 2026
Response after Non-Final Action
Jun 22, 2026
Request for Continued Examination
Jun 28, 2026
Response after Non-Final Action
Aug 04, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688282
MALICIOUS ACTIVITY DETECTION FOR CLOUD COMPUTING PLATFORMS
3y 1m to grant Granted Jul 21, 2026
Patent 12688312
CONSISTENT ACCESS CONTROL LISTS ACROSS FILE SERVERS FOR LOCAL USERS IN A DISTRIBUTED FILE SERVER ENVIRONMENT
1y 7m to grant Granted Jul 21, 2026
Patent 12670245
UTILIZING MACHINE-LEARNING MODELS TO DETERMINE TAKE-OVER SCORES AND INTELLIGENTLY SECURE DIGITAL ACCOUNT FEATURES
1y 6m to grant Granted Jun 30, 2026
Patent 12657492
SYSTEMS, METHODS AND APPARATUS FOR EVALUATING STATUS OF COMPUTING DEVICE USER
2y 8m to grant Granted Jun 16, 2026
Patent 12645782
CAPTCHA AUTHENTICATION USING SMART WATCH SCRIBBLE
2y 4m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
83%
Grant Probability
96%
With Interview (+12.5%)
2y 10m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 806 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month